CVE-2024-21885 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 7 months, 3 weeks ago Xorg-x11-server: heap buffer overflow in xisenddevicehierarchyevent A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated array length when certain new device IDs are added to the xXIHierarchyInfo struct. This can trigger a heap buffer overflow condition, which may lead to an application crash or remote code execution in SSH X11 forwarding environments. Affected products tigervnc * xwayland <23.2.4 * xorg-server ==1.21.1.7 <21.1.11 * xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0 pkgs.xorg.xvfb nixos-unstable 21.1.14 nixos-unstable-small 21.1.14 nixpkgs-unstable 21.1.14 pkgs.xorg.xorgserver nixos-unstable 21.1.14 nixos-unstable-small 21.1.14 nixpkgs-unstable 21.1.14
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0
CVE-2025-27288 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 8 months ago WordPress File Icons Plugin <= 2.1 - Reflected Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BjornW File Icons allows Reflected XSS. This issue affects File Icons: from n/a through 2.1. Affected products file-icons =<2.1 Matching in nixpkgs pkgs.emacsPackages.magit-file-icons nixos-unstable 20240627.1228 nixos-unstable-small 20240627.1228 nixpkgs-unstable 20240627.1228 pkgs.vscode-extensions.file-icons.file-icons File-specific icons in VSCode for improved visual grepping nixos-unstable 1.0.29 nixos-unstable-small 1.0.29 nixpkgs-unstable 1.0.29
pkgs.emacsPackages.magit-file-icons nixos-unstable 20240627.1228 nixos-unstable-small 20240627.1228 nixpkgs-unstable 20240627.1228
pkgs.vscode-extensions.file-icons.file-icons File-specific icons in VSCode for improved visual grepping nixos-unstable 1.0.29 nixos-unstable-small 1.0.29 nixpkgs-unstable 1.0.29
CVE-2025-39438 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 8 months ago WordPress Theme Changer plugin <= 1.3 - Cross Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability in momen2009 Theme Changer allows Cross Site Request Forgery. This issue affects Theme Changer: from n/a through 1.3. Affected products theme-changer =<1.3 Matching in nixpkgs pkgs.emacsPackages.theme-changer nixos-unstable 20230904.1706 nixos-unstable-small 20230904.1706 nixpkgs-unstable 20230904.1706 pkgs.gnomeExtensions.dm-theme-changer Automatically change theme styles when dark mode is enabled or disabled. nixos-unstable 4 nixos-unstable-small 4 nixpkgs-unstable 4 Package maintainers: 1 @honnip Jung seungwoo <me@honnip.page>
pkgs.emacsPackages.theme-changer nixos-unstable 20230904.1706 nixos-unstable-small 20230904.1706 nixpkgs-unstable 20230904.1706
pkgs.gnomeExtensions.dm-theme-changer Automatically change theme styles when dark mode is enabled or disabled. nixos-unstable 4 nixos-unstable-small 4 nixpkgs-unstable 4
CVE-2024-22051 9.8 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 8 months ago CommonMarker Integer Overflow Vulnerability CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns. Affected products commonmarker <0.23.4 Matching in nixpkgs pkgs.rubyPackages.commonmarker nixos-unstable 0.23.10 nixos-unstable-small 0.23.10 pkgs.rubyPackages_3_1.commonmarker nixos-unstable 0.23.10 nixos-unstable-small 0.23.10 nixpkgs-unstable 0.23.10 pkgs.rubyPackages_3_2.commonmarker nixos-unstable 0.23.10 nixos-unstable-small 0.23.10 nixpkgs-unstable 0.23.10 pkgs.rubyPackages_3_3.commonmarker nixos-unstable 0.23.10 nixos-unstable-small 0.23.10 nixpkgs-unstable 0.23.10 pkgs.rubyPackages_3_4.commonmarker nixos-unstable 0.23.10 nixos-unstable-small 0.23.10 nixpkgs-unstable 0.23.10
pkgs.rubyPackages_3_1.commonmarker nixos-unstable 0.23.10 nixos-unstable-small 0.23.10 nixpkgs-unstable 0.23.10
pkgs.rubyPackages_3_2.commonmarker nixos-unstable 0.23.10 nixos-unstable-small 0.23.10 nixpkgs-unstable 0.23.10
pkgs.rubyPackages_3_3.commonmarker nixos-unstable 0.23.10 nixos-unstable-small 0.23.10 nixpkgs-unstable 0.23.10
pkgs.rubyPackages_3_4.commonmarker nixos-unstable 0.23.10 nixos-unstable-small 0.23.10 nixpkgs-unstable 0.23.10
CVE-2025-39434 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 8 months ago WordPress Avatar plugin <= 0.1.4 - Insecure Direct Object References (IDOR) vulnerability Authorization Bypass Through User-Controlled Key vulnerability in Scott Taylor Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Avatar: from n/a through 0.1.4. Affected products avatar =<0.1.4 Matching in nixpkgs pkgs.yunfaavatar Utility for automatic centralized changing of avatar in Github, Discord, Steam, Shikimori, and many more nixos-unstable 0.2.0 nixos-unstable-small 0.2.0 nixpkgs-unstable 0.2.0 pkgs.libsForQt5.libgravatar nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5 pkgs.kdePackages.libgravatar Library that provides Gravatar support nixos-unstable 24.08.3 nixos-unstable-small 24.08.3 nixpkgs-unstable 24.08.3 pkgs.gnomeExtensions.gravatar Synchronize GNOME Shell user icon with Gravatar. nixos-unstable 6 nixos-unstable-small 6 nixpkgs-unstable 6 pkgs.haskellPackages.gravatar Generate Gravatar image URLs nixos-unstable 0.8.1 nixos-unstable-small 0.8.1 nixpkgs-unstable 0.8.1 pkgs.haskellPackages.libravatar Use Libravatar, the decentralized avatar delivery service nixos-unstable 0.4.0.2 nixos-unstable-small 0.4.0.2 nixpkgs-unstable 0.4.0.2 pkgs.rubyPackages.jekyll-avatar nixos-unstable 0.8.0 nixos-unstable-small 0.8.0 pkgs.plasma5Packages.libgravatar nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5 pkgs.python311Packages.libgravatar Library that provides a Python 3 interface for the Gravatar API nixos-unstable 1.0.4 nixos-unstable-small 1.0.4 nixpkgs-unstable 1.0.4 pkgs.python312Packages.libgravatar Library that provides a Python 3 interface for the Gravatar API nixos-unstable 1.0.4 nixos-unstable-small 1.0.4 nixpkgs-unstable 1.0.4 pkgs.rubyPackages_3_1.jekyll-avatar nixos-unstable 0.8.0 nixos-unstable-small 0.8.0 nixpkgs-unstable 0.8.0 pkgs.rubyPackages_3_2.jekyll-avatar nixos-unstable 0.8.0 nixos-unstable-small 0.8.0 nixpkgs-unstable 0.8.0 pkgs.rubyPackages_3_3.jekyll-avatar nixos-unstable 0.8.0 nixos-unstable-small 0.8.0 nixpkgs-unstable 0.8.0 pkgs.rubyPackages_3_4.jekyll-avatar nixos-unstable 0.8.0 nixos-unstable-small 0.8.0 nixpkgs-unstable 0.8.0 pkgs.python311Packages.flask-gravatar Small and simple integration of gravatar into flask nixos-unstable 0.5.0 nixos-unstable-small 0.5.0 nixpkgs-unstable 0.5.0 pkgs.python312Packages.flask-gravatar Small and simple integration of gravatar into flask nixos-unstable 0.5.0 nixos-unstable-small 0.5.0 nixpkgs-unstable 0.5.0 pkgs.python311Packages.django-gravatar2 Essential Gravatar support for Django nixos-unstable gravatar2-1.4.5 nixos-unstable-small gravatar2-1.4.5 nixpkgs-unstable gravatar2-1.4.5 pkgs.python312Packages.django-gravatar2 Essential Gravatar support for Django nixos-unstable gravatar2-1.4.5 nixos-unstable-small gravatar2-1.4.5 nixpkgs-unstable gravatar2-1.4.5 pkgs.perl538Packages.MojoliciousPluginGravatar Globally Recognized Avatars for Mojolicious nixos-unstable 0.04 nixos-unstable-small 0.04 nixpkgs-unstable 0.04 pkgs.perl540Packages.MojoliciousPluginGravatar Globally Recognized Avatars for Mojolicious nixos-unstable 0.04 nixos-unstable-small 0.04 nixpkgs-unstable 0.04 pkgs.gnomeExtensions.user-avatar-in-quick-settings Display the user avatar in the Quick Settings menu, part of the "System" settings nixos-unstable 8 nixos-unstable-small 8 nixpkgs-unstable 8 Package maintainers: 13 @gador Florian Brandes <florian.brandes@posteo.de> @yunfachi Yunfachi <yunfachi@gmail.com> @ttuegel Thomas Tuegel <ttuegel@mailbox.org> @vandenoever Jos van den Oever <jos@vandenoever.info> @nyanloutre Paul Trehiou <paul@nyanlout.re> @stigtsp Stig Palmquist <stig@stig.io> @honnip Jung seungwoo <me@honnip.page> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru> @NickCao Nick Cao <nickcao@nichi.co> @K900 Ilya K. <me@0upti.me> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev> @mjm Matt Moriarity <matt@mattmoriarity.com>
pkgs.yunfaavatar Utility for automatic centralized changing of avatar in Github, Discord, Steam, Shikimori, and many more nixos-unstable 0.2.0 nixos-unstable-small 0.2.0 nixpkgs-unstable 0.2.0
pkgs.libsForQt5.libgravatar nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5
pkgs.kdePackages.libgravatar Library that provides Gravatar support nixos-unstable 24.08.3 nixos-unstable-small 24.08.3 nixpkgs-unstable 24.08.3
pkgs.gnomeExtensions.gravatar Synchronize GNOME Shell user icon with Gravatar. nixos-unstable 6 nixos-unstable-small 6 nixpkgs-unstable 6
pkgs.haskellPackages.gravatar Generate Gravatar image URLs nixos-unstable 0.8.1 nixos-unstable-small 0.8.1 nixpkgs-unstable 0.8.1
pkgs.haskellPackages.libravatar Use Libravatar, the decentralized avatar delivery service nixos-unstable 0.4.0.2 nixos-unstable-small 0.4.0.2 nixpkgs-unstable 0.4.0.2
pkgs.plasma5Packages.libgravatar nixos-unstable 23.08.5 nixos-unstable-small 23.08.5 nixpkgs-unstable 23.08.5
pkgs.python311Packages.libgravatar Library that provides a Python 3 interface for the Gravatar API nixos-unstable 1.0.4 nixos-unstable-small 1.0.4 nixpkgs-unstable 1.0.4
pkgs.python312Packages.libgravatar Library that provides a Python 3 interface for the Gravatar API nixos-unstable 1.0.4 nixos-unstable-small 1.0.4 nixpkgs-unstable 1.0.4
pkgs.rubyPackages_3_1.jekyll-avatar nixos-unstable 0.8.0 nixos-unstable-small 0.8.0 nixpkgs-unstable 0.8.0
pkgs.rubyPackages_3_2.jekyll-avatar nixos-unstable 0.8.0 nixos-unstable-small 0.8.0 nixpkgs-unstable 0.8.0
pkgs.rubyPackages_3_3.jekyll-avatar nixos-unstable 0.8.0 nixos-unstable-small 0.8.0 nixpkgs-unstable 0.8.0
pkgs.rubyPackages_3_4.jekyll-avatar nixos-unstable 0.8.0 nixos-unstable-small 0.8.0 nixpkgs-unstable 0.8.0
pkgs.python311Packages.flask-gravatar Small and simple integration of gravatar into flask nixos-unstable 0.5.0 nixos-unstable-small 0.5.0 nixpkgs-unstable 0.5.0
pkgs.python312Packages.flask-gravatar Small and simple integration of gravatar into flask nixos-unstable 0.5.0 nixos-unstable-small 0.5.0 nixpkgs-unstable 0.5.0
pkgs.python311Packages.django-gravatar2 Essential Gravatar support for Django nixos-unstable gravatar2-1.4.5 nixos-unstable-small gravatar2-1.4.5 nixpkgs-unstable gravatar2-1.4.5
pkgs.python312Packages.django-gravatar2 Essential Gravatar support for Django nixos-unstable gravatar2-1.4.5 nixos-unstable-small gravatar2-1.4.5 nixpkgs-unstable gravatar2-1.4.5
pkgs.perl538Packages.MojoliciousPluginGravatar Globally Recognized Avatars for Mojolicious nixos-unstable 0.04 nixos-unstable-small 0.04 nixpkgs-unstable 0.04
pkgs.perl540Packages.MojoliciousPluginGravatar Globally Recognized Avatars for Mojolicious nixos-unstable 0.04 nixos-unstable-small 0.04 nixpkgs-unstable 0.04
pkgs.gnomeExtensions.user-avatar-in-quick-settings Display the user avatar in the Quick Settings menu, part of the "System" settings nixos-unstable 8 nixos-unstable-small 8 nixpkgs-unstable 8
CVE-2025-39436 9.1 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 8 months ago WordPress I Draw <= 1.0 - Arbitrary File Upload Vulnerability Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw allows Using Malicious Files. This issue affects I Draw: from n/a through 1.0. Affected products idraw =<1.0 Matching in nixpkgs pkgs.kanjidraw Handwritten kanji recognition nixos-unstable 0.2.3 nixos-unstable-small 0.2.3 nixpkgs-unstable 0.2.3 pkgs.jitsi-excalidraw Excalidraw collaboration backend for Jitsi nixos-unstable 21 nixos-unstable-small 21 nixpkgs-unstable 21 pkgs.excalidraw_export CLI to export Excalidraw drawings to SVG and PDF nixos-unstable 1.1.0 nixos-unstable-small 1.1.0 nixpkgs-unstable 1.1.0 pkgs.tests.pkg-config.defaultPkgConfigPackages.hidapi-hidraw Test whether hidapi-0.14.0 exposes pkg-config modules hidapi-hidraw nixos-unstable ??? nixos-unstable-small nixpkgs-unstable Package maintainers: 4 @prusnak Pavol Rusnak <pavol@rusnak.io> @camillemndn Camille M. <camillemondon@free.fr> @venikx Kevin De Baerdemaeker <code@venikx.com> @obfusk FC Stegerman <flx@obfusk.net>
pkgs.kanjidraw Handwritten kanji recognition nixos-unstable 0.2.3 nixos-unstable-small 0.2.3 nixpkgs-unstable 0.2.3
pkgs.jitsi-excalidraw Excalidraw collaboration backend for Jitsi nixos-unstable 21 nixos-unstable-small 21 nixpkgs-unstable 21
pkgs.excalidraw_export CLI to export Excalidraw drawings to SVG and PDF nixos-unstable 1.1.0 nixos-unstable-small 1.1.0 nixpkgs-unstable 1.1.0
pkgs.tests.pkg-config.defaultPkgConfigPackages.hidapi-hidraw Test whether hidapi-0.14.0 exposes pkg-config modules hidapi-hidraw nixos-unstable ??? nixos-unstable-small nixpkgs-unstable
CVE-2025-27324 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 8 months ago WordPress 17TRACK for WooCommerce Plugin <= 1.2.10 - Reflected Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 17track 17TRACK for WooCommerce allows Reflected XSS. This issue affects 17TRACK for WooCommerce: from n/a through 1.2.10. Affected products 17track =<1.2.10 Matching in nixpkgs
CVE-2025-39580 5.8 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 8 months ago WordPress Dashi <= 3.1.8 - Broken Access Control Vulnerability Missing Authorization vulnerability in jidaikobo Dashi allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dashi: from n/a through 3.1.8. Affected products dashi =<3.1.8 Matching in nixpkgs pkgs.dashing Dash Generator Script for Any HTML nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0 pkgs.python311Packages.dashing Terminal dashboards for Python nixos-unstable 0.1.0 nixos-unstable-small 0.1.0 nixpkgs-unstable 0.1.0 pkgs.python312Packages.dashing Terminal dashboards for Python nixos-unstable 0.1.0 nixos-unstable-small 0.1.0 nixpkgs-unstable 0.1.0 Package maintainers: 1 @juliusrickert Julius Rickert <nixpkgs@juliusrickert.de>
pkgs.dashing Dash Generator Script for Any HTML nixos-unstable 0.4.0 nixos-unstable-small 0.4.0 nixpkgs-unstable 0.4.0
pkgs.python311Packages.dashing Terminal dashboards for Python nixos-unstable 0.1.0 nixos-unstable-small 0.1.0 nixpkgs-unstable 0.1.0
pkgs.python312Packages.dashing Terminal dashboards for Python nixos-unstable 0.1.0 nixos-unstable-small 0.1.0 nixpkgs-unstable 0.1.0
CVE-2025-24655 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 8 months ago WordPress Wishlist Plugin <= 1.0.39 - Reflected Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Wishlist allows Reflected XSS. This issue affects Wishlist: from n/a through 1.0.39. Affected products wishlist =<1.0.39 Matching in nixpkgs pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable 0.15.0 nixos-unstable-small 0.15.0 nixpkgs-unstable 0.15.0 Package maintainers: 2 @caarlos0 Carlos A Becker <carlos@becker.software> @penguwin Nicolas Martin <penguwin@penguwin.eu>
pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable 0.15.0 nixos-unstable-small 0.15.0 nixpkgs-unstable 0.15.0
CVE-2025-32911 9.0 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 8 months ago Libsoup: double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" ghashtable value A flaw was found in libsoup, which is vulnerable to a use-after-free memory issue not on the heap in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server. Affected products libsoup * <3.6.3 libsoup3 mingw-freetype * spice-client-win * Matching in nixpkgs pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable 3.6.0 nixos-unstable-small 3.6.0 nixpkgs-unstable 3.6.0 pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable 2.74.3 nixos-unstable-small 2.74.3 nixpkgs-unstable 2.74.3 pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable 2.4 nixos-unstable-small 2.4 nixpkgs-unstable 2.4 Package maintainers: 6 @jtojnar Jan Tojnar <jtojnar@gmail.com> @bobby285271 Bobby Rong <rjl931189261@126.com> @lovek323 Jason O'Conal <jason@oconal.id.au> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
pkgs.libsoup_3 HTTP client/server library for GNOME nixos-unstable 3.6.0 nixos-unstable-small 3.6.0 nixpkgs-unstable 3.6.0
pkgs.libsoup_2_4 HTTP client/server library for GNOME nixos-unstable 2.74.3 nixos-unstable-small 2.74.3 nixpkgs-unstable 2.74.3
pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4" Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4 nixos-unstable 2.4 nixos-unstable-small 2.4 nixpkgs-unstable 2.4